Security & compliance

Built to be examined, not just audited.

Our compliance platform runs inside scheduled banks, where a failed check is a regulatory event. The controls that work demands are the controls every client gets.

40+
Banks reached through our compliance platform
3
Deployment models, including on-premise
365
Days of monitoring on hosted systems
2
Jurisdictions we contract under
01 Controls

What is in place on every deployment.

Not a tier you upgrade to. These apply whether you are a bank or a single clinic.

Access control
Role-based permissions on every module
Clinical and financial data separated by role
Credentials revoked the day someone leaves
Least-privilege access for our own engineers
Audit trail
Every screening decision logged with its inputs
Who changed what, when, and from where
Logs retained on a defined window, tamper-evident
Exportable for your examiner, not just for us
Data protection
TLS in transit, encryption at rest
Daily automated backups, restore tested
No client production data in development
Full export on request, in a usable format
Infrastructure
Security hardening on every server we configure
Continuous uptime and integrity monitoring
Patching on a maintained schedule
Isolated instances for private cloud clients
Software assurance
Code review before anything reaches production
Manual and automated testing, including performance
Security audit and vulnerability testing as a service
Staged releases with rollback available
People
Confidentiality obligations in every contract
Named engineers on regulated deployments
Compliance function held at the UK entity
No subcontracting of client work without consent
02 Data residency

Where your data sits is your decision.

Three deployment models, and the compliance consequence of each stated plainly.

Cloud SaaS
We host, patch and monitor it on infrastructure we manage. Fastest to deploy and the lowest operational burden on you.
Data location Our managed cloud
Patching Handled by us
Suits Most commercial clients
Private cloud
Your own isolated instance and database, not shared with any other client. For firms with data residency obligations.
Data location Dedicated instance
Patching Handled by us, scheduled with you
Suits Financial, healthcare
On-premise
Installed on your own servers, behind your own firewall. Data never leaves your environment at any point.
Data location Entirely yours
Patching Scheduled maintenance windows
Suits Banks, government, defence
03 Regulatory context

The obligations we build against.

Our clients are regulated; we are the vendor inside their perimeter. That means our software has to satisfy their examiners, not ours.

AML and financial crime obligations
Our screening platform is built so a bank can evidence what it checked — sanctions, PEP, adverse media, criminal records — against the date and list version used.
Patient confidentiality
Hospital deployments separate clinical from financial access, so billing staff cannot browse medical records to do their job.
UK entity obligations
MHS Planet Limited, company number 14578596, holds the compliance function and the international contracting relationships.
Bangladesh operations
MHS Planet operates under trade licence TRAD/DNCC/013196/2023, with delivery, hosting and support run from the Dhaka office.
Certification status

We state this plainly rather than implying more than we hold.

Contractual data protection terms
Processor obligations written into client agreements.
In place
Security audit & penetration testing
Offered as a service and run on our own platforms.
In place
ISO 27001 certification
Controls modelled on it; formal certification not yet obtained.
Not yet held
SOC 2 attestation
Available on request as a roadmap item for enterprise clients.
Not yet held
Request the security pack
04 If something goes wrong

Incident response, in the order it happens.

You will hear from us before you hear from anyone else. That is the commitment.

01
Detect
Monitoring flags it, or a client reports it to the support desk.
02
Contain
Limit exposure first — isolate, revoke, or take the affected component offline.
03
Notify
We contact affected clients directly with what we know, including what we do not yet know.
04
Remediate
Fix, patch and verify, with a restore from backup if data integrity is in question.
05
Report
A written account: cause, impact, timeline and what changes so it does not recur.
Reporting a vulnerability
Found something in one of our platforms? Tell us directly — we do not pursue researchers who report in good faith.
Report privately
Due diligence questions

Asked by every procurement team.

Are you ISO 27001 certified?
No, and we will not imply otherwise. Our controls are modelled on it and shaped by what our banking clients require of their vendors, but we do not currently hold the certification. If it is a procurement requirement, tell us early and we will discuss the timeline honestly.
Who at MHS Planet can see our data?
Only staff whose role requires it, only when support, migration or fault diagnosis calls for it, and access is logged. On-premise deployments give us no standing access at all.
Can we keep our data inside Bangladesh?
Yes — private cloud on infrastructure specified with you, or on-premise on your own servers. This is the usual answer for banks and government bodies.
What happens to our data if we leave?
You get a full export in a usable format, and on request we confirm deletion from our systems, subject to any retention we are legally required to observe.
Do you subcontract development work?
No. All engineering is done by our own team in Dhaka, with the compliance function at the UK entity. Nothing goes to an outside contractor without your written consent.
Can we audit you?
Yes. Enterprise clients can review our controls, and we will complete your vendor security questionnaire. Request the security pack to start.